Total
27865 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2001-0900 | 1 Francisco Burzi | 1 Gallery | 2017-10-09 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in modules.php in Gallery before 1.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the include parameter. | |||||
| CVE-2001-0901 | 1 Hypermail Development | 1 Hypermail | 2017-10-09 | 7.5 HIGH | N/A |
| Hypermail allows remote attackers to execute arbitrary commands on a server supporting SSI via an attachment with a .shtml extension, which is archived on the server and can then be executed by requesting the URL for the attachment. | |||||
| CVE-2000-0632 | 1 Lsoft | 1 Listserv | 2017-10-09 | 7.5 HIGH | N/A |
| Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string. | |||||
| CVE-2000-0634 | 1 Stalker | 1 Communigate Pro | 2017-10-09 | 5.0 MEDIUM | N/A |
| The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |||||
| CVE-2001-0906 | 1 Tetex | 1 Tetex | 2017-10-09 | 6.2 MEDIUM | N/A |
| teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produced when printing .dvi files using lpr. | |||||
| CVE-2001-0574 | 1 Jason Rahaim | 1 Mp3mystic | 2017-10-09 | 5.0 MEDIUM | N/A |
| Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via a '..' (dot dot) in the URL. | |||||
| CVE-2000-0635 | 1 Akopia | 1 Minivend | 2017-10-09 | 7.5 HIGH | N/A |
| The view_page.html sample page in the MiniVend shopping cart program allows remote attackers to execute arbitrary commands via shell metacharacters. | |||||
| CVE-2000-0636 | 1 Hp | 1 Jetdirect | 2017-10-09 | 5.0 MEDIUM | N/A |
| HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a malformed FTP quote command. | |||||
| CVE-1999-1243 | 1 Sgi | 1 Irix | 2017-10-09 | 4.6 MEDIUM | N/A |
| SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and gain privileges. | |||||
| CVE-2001-0905 | 1 Procmail | 1 Procmail | 2017-10-09 | 6.2 MEDIUM | N/A |
| Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal while a signal handling routine is already running. | |||||
| CVE-2000-0638 | 1 Sean Macguire | 1 Big Brother | 2017-10-09 | 10.0 HIGH | N/A |
| bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack on the HOSTSVC parameter. | |||||
| CVE-2000-0639 | 1 Sean Macguire | 1 Big Brother | 2017-10-09 | 7.5 HIGH | N/A |
| The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows remote attackers to execute arbitrary commands by using bbd to upload a file whose extension will cause it to be executed as a CGI script by the web server. | |||||
| CVE-2000-0640 | 1 Steve Poulsen | 1 Guildftpd | 2017-10-09 | 7.5 HIGH | N/A |
| Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, which provides different error messages depending on whether the file exists or not. | |||||
| CVE-2000-0641 | 1 Michael Lamont | 1 Savant Webserver | 2017-10-09 | 7.5 HIGH | N/A |
| Savant web server allows remote attackers to execute arbitrary commands via a long GET request. | |||||
| CVE-2001-0909 | 1 Microsoft | 1 Windows Xp | 2017-10-09 | 7.5 HIGH | N/A |
| Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL. | |||||
| CVE-1999-1246 | 1 Microsoft | 1 Site Server | 2017-10-09 | 7.5 HIGH | N/A |
| Direct Mailer feature in Microsoft Site Server 3.0 saves user domain names and passwords in plaintext in the TMLBQueue network share, which has insecure default permissions, allowing remote attackers to read the passwords and gain privileges. | |||||
| CVE-2000-0642 | 1 Itafrica | 1 Webactive | 2017-10-09 | 5.0 MEDIUM | N/A |
| The default configuration of WebActive HTTP Server 1.00 stores the web access log active.log in the document root, which allows remote attackers to view the logs by directly requesting the page. | |||||
| CVE-2000-0643 | 1 Itafrica | 1 Webactive | 2017-10-09 | 5.0 MEDIUM | N/A |
| Buffer overflow in WebActive HTTP Server 1.00 allows remote attackers to cause a denial of service via a long URL. | |||||
| CVE-2000-0644 | 1 Texas Imperial Software | 1 Wftpd | 2017-10-09 | 5.0 MEDIUM | N/A |
| WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST command is still executing. | |||||
| CVE-1999-1249 | 1 Hp | 1 Hp-ux | 2017-10-09 | 4.6 MEDIUM | N/A |
| movemail in HP-UX 10.20 has insecure permissions, which allows local users to gain privileges. | |||||
